Vulnfeed

Archives
Log in
Subscribe
September 18, 2026

[vulnfeed] 27 critical CVEs — 2026-09-18 20:00 UTC

vulnfeed Critical alert — 2026-09-18 22:45 UTC
27 new critical CVEs in the last 5 hours — 27 CVSS ≥ 9.0
New vulnerabilities
CVE-2026-61781CRITICAL
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_par
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it w
CVSS 9.9
CVE-2026-80442CRITICAL
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execut
CVSS 9.9
CVE-2026-84064CRITICAL
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL command
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
CVSS 9.9
CVE-2026-84075CRITICAL
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.
CVSS 9.9
CVE-2026-84078CRITICAL
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerS
IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentiall
CVSS 9.9
CVE-2025-66455CRITICAL
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2
LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane
CVSS 9.8
CVE-2026-61550CRITICAL
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JS
Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauth
CVSS 9.8
CVE-2026-58264CRITICAL
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the Flui
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bo
CVSS 9.8
CVE-2026-80441CRITICAL
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability
IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability in the generateInsertQuery functionality of change-tracker-data.sql. A remote attacker co
CVSS 9.8
CVE-2026-81657CRITICAL
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on t
IBM Guardium Data Protection 12.2 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
CVSS 9.8
CVE-2026-82340CRITICAL
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-contr
IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflective method dispatch in the Change Audit System (CAS) listener. A network atta
CVSS 9.8
CVE-2026-82967CRITICAL
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated rem
IBM Guardium Data Protection 12.2 is vulnerable to an authentication bypass that allows an unauthenticated remote attacker to bypass IP-based access controls and access the Guardium management interfa
CVSS 9.8
CVE-2026-84082CRITICAL
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to impro
IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.
CVSS 9.8
CVE-2026-82832CRITICAL
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to
IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.
CVSS 9.6
CVE-2023-54399CRITICAL
Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the
Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-
CVSS 9.3

Live feed →  ·  Notification settings

vulnfeed critical alerts — vulnfeed.it. Unsubscribe

Don't miss what's next. Subscribe to Vulnfeed:
← Newer [vulnfeed] 3 critical CVEs — 2026-09-19 04:00 UTC Older → [vulnfeed] 22 critical CVEs — 2026-09-18 16:00 UTC
Powered by Buttondown, the easiest way to start and grow your newsletter.